CVE-2026-42835
Last Modified: 10 Jun 2026Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Teams for Android allows an authorized attacker to disclose information over a network.
CVE-2026-42829
Last Modified: 11 Jun 2026Improper access control in Windows Administrator Protection allows an authorized attacker to bypass a security feature locally.
CVE-2026-42828
Last Modified: 10 Jun 2026Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
CVE-2026-40371
Last Modified: 10 Jun 2026Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
CVE-2026-33113
Last Modified: 8 Jul 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-26142
Last Modified: 10 Jun 2026Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
CVE-2026-50508
Last Modified: 10 Jun 2026Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-49161
Last Modified: 10 Jun 2026Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
CVE-2026-48583
Last Modified: 10 Jun 2026Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVE-2026-48578
Last Modified: 8 Jul 2026Improper access control in Windows Secure Boot allows an authorized attacker to elevate privileges locally.
CVE-2026-48576
Last Modified: 8 Jul 2026No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48575
Last Modified: 10 Jun 2026Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48573
Last Modified: 8 Jul 2026No cwe for this issue in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48570
Last Modified: 10 Jun 2026Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48568
Last Modified: 10 Jun 2026Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-48566
Last Modified: 14 Aug 2026Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2026-48563
Last Modified: 8 Jul 2026Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-47654
Last Modified: 8 Jul 2026Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-47652
Last Modified: 8 Jul 2026Heap-based buffer overflow in Windows Hyper-V allows an authorized attacker to execute code locally.
CVE-2026-47653
Last Modified: 8 Jul 2026Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-47648
Last Modified: 10 Jun 2026Untrusted search path in Windows Storage allows an authorized attacker to elevate privileges locally.
CVE-2026-45588
Last Modified: 11 Jun 2026Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
CVE-2026-47641
Last Modified: 8 Jul 2026Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-47639
Last Modified: 8 Jul 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-47638
Last Modified: 10 Jun 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-47637
Last Modified: 10 Jun 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
CVE-2026-47636
Last Modified: 8 Jul 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-47635
Last Modified: 8 Jul 2026Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-41098
Last Modified: 9 Jun 2026Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
CVE-2026-47631
Last Modified: 15 Jun 2026Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-47298
Last Modified: 12 Jun 2026Improper authorization in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
CVE-2026-32193
Last Modified: 10 Jun 2026Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
CVE-2026-41092
Last Modified: 15 Jun 2026Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
CVE-2026-47292
Last Modified: 15 Jun 2026Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
CVE-2026-47291
Last Modified: 10 Jun 2026Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
CVE-2026-47289
Last Modified: 12 Jun 2026Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-47288
Last Modified: 10 Jun 2026Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.
CVE-2026-47287
Last Modified: 9 Jun 2026Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
CVE-2026-45657
Last Modified: 10 Jun 2026Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
CVE-2026-45656
Last Modified: 15 Jun 2026Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
CVE-2026-45655
Last Modified: 15 Jun 2026Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-45650
Last Modified: 10 Jun 2026User interface (ui) misrepresentation of critical information in Microsoft Bing allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-45649
Last Modified: 10 Jun 2026Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
CVE-2026-45648
Last Modified: 11 Jun 2026Stack-based buffer overflow in Active Directory Domain Services allows an authorized attacker to execute code over a network.
CVE-2026-45645
Last Modified: 8 Jul 2026Untrusted pointer dereference in Microsoft Office allows an unauthorized attacker to execute code locally.
CVE-2026-45643
Last Modified: 11 Jun 2026Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVE-2026-45642
Last Modified: 11 Jun 2026Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
CVE-2026-45634
Last Modified: 12 Jun 2026Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
CVE-2026-45641
Last Modified: 8 Jul 2026Access of resource using incompatible type ('type confusion') in Windows Hyper-V allows an unauthorized attacker to execute code locally.
CVE-2026-45607
Last Modified: 11 Jun 2026Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
